Broccoli Oss GCP Deploy
besimple-oss/broccoli
Deploy this repository to a new Google Cloud project using the repo's existing Cloud Run, Cloud Run Jobs, Cloud SQL, Secret Manager, and Artifact Registry scripts.
A skill your agent uses when running a small product on core Google Cloud via the gcloud CLI: a project, Cloud Run deploys, a locked-down Cloud Storage bucket, managed Cloud SQL, and least-privilege…
$ npx skills add ericrisco/rsc-harness --skill gcp-essentials -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness gcp-essentials --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gcp-essentials .claude/skills/gcp-essentials && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "gcp-essentials" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gcp-essentials into .claude/skills/gcp-essentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gcp-essentials", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/gcp-essentialsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill gcp-essentials -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness gcp-essentials --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/gcp-essentials .agents/skills/gcp-essentials && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "gcp-essentials" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gcp-essentials into .agents/skills/gcp-essentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gcp-essentials", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill gcp-essentials -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness gcp-essentials --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/gcp-essentials .cursor/skills/gcp-essentials && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "gcp-essentials" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gcp-essentials into .cursor/skills/gcp-essentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gcp-essentials", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/gcp-essentials--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill gcp-essentials -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness gcp-essentials --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/gcp-essentials .gemini/skills/gcp-essentials && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "gcp-essentials" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gcp-essentials into .gemini/skills/gcp-essentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gcp-essentials", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness gcp-essentialsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill gcp-essentials -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/gcp-essentials .github/skills/gcp-essentials && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "gcp-essentials" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gcp-essentials into .github/skills/gcp-essentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gcp-essentials", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill gcp-essentials -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness gcp-essentials --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/gcp-essentials .opencode/skills/gcp-essentials && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "gcp-essentials" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/gcp-essentials into .opencode/skills/gcp-essentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "gcp-essentials", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
gcp-essentialsA skill your agent uses when running a small product on core Google Cloud via the gcloud CLI: a project, Cloud Run deploys, a locked-down Cloud Storage bucket, managed Cloud SQL, and least-privilege…
GCP Essentials is an agent skill from ericrisco/rsc-harness. Use when running a small product on core Google Cloud via the gcloud CLI: a project, Cloud Run deploys, a locked-down Cloud Storage bucket, managed Cloud SQL, and least-privilege IAM wiring them together. NOT AWS (that is aws-essentials), NOT the CI pipeline that ships the image (that is deployment), NOT Postgres schema/query tuning (that is postgresdb).
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/deploy-recipes.md`).
It sits in DevOps & Cloud, covering CI/CD, Query optimization and SQL. It works with Google Cloud, Amazon Web Services, Cloud Run and PostgreSQL. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gcloudopensslbashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gcloud, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DB_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GCP Essentials loads about 3.7k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 1,157 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,157 words, ~3,721 tokens.
.claude/skills/gcp-essentials/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Get a small product running on the core of Google Cloud — safely and cheaply — with
the gcloud CLI as the source of truth. The console is fine for reading; the CLI is
what you commit, review, and reproduce. Bias toward secure-by-default and near-zero
bill, not "every GCP service".
Four primitives carry most products, plus the project/billing scaffold under them:
Out of scope, route elsewhere: AWS -> ../aws-essentials/SKILL.md.
Building/shipping the image itself -> ../docker/SKILL.md
/ ../github-actions/SKILL.md / ../deployment/SKILL.md.
Postgres schema/index/query tuning -> ../postgresdb/SKILL.md.
App-level injection/secret-handling review -> ../secure-coding/SKILL.md.
Logging/alerting/SLOs as a practice -> ../monitoring/SKILL.md.
Backup strategy as a discipline -> ../backups/SKILL.md.
One-click PaaS where you never touch IAM/VPC -> ../vercel/SKILL.md
/ ../railway/SKILL.md / ../render/SKILL.md
/ ../fly-io/SKILL.md.
One project per environment (e.g. acme-prod, acme-staging). Projects are the IAM
and billing boundary; mixing prod and dev in one project is how a staging credential
deletes prod data.
# Create the project and point gcloud at it
gcloud projects create acme-prod --name="Acme prod"
gcloud config set project acme-prod
gcloud config set run/region europe-west1 # set once; every run command inherits it
# Link billing (no billing = APIs 403). Find your account id first:
gcloud billing accounts list
gcloud billing projects link acme-prod --billing-account=0X0X0X-0X0X0X-0X0X0X
# Enable ONLY the APIs this product needs. Why: every enabled API widens the
# attack surface and some bill the moment they are on.
gcloud services enable \
run.googleapis.com \
sqladmin.googleapis.com \
storage.googleapis.com \
secretmanager.googleapis.com \
iam.googleapis.comA binding is member + role on a resource. Members come in three flavours you will
actually type:
| Member type | Syntax | Use for |
|---|---|---|
| User | user:alice@acme.com | a human |
| Group | group:eng@acme.com | a team (manage in Workspace) |
| Service account | serviceAccount:NAME@PROJ.iam.gserviceaccount.com | a workload identity |
Grant grammar — bind at the smallest resource that works (project here, but prefer bucket/instance scope when the role supports it):
gcloud projects add-iam-policy-binding acme-prod \
--member="serviceAccount:api@acme-prod.iam.gserviceaccount.com" \
--role="roles/cloudsql.client"Choosing a role:
| Role kind | Example | When |
|---|---|---|
| Primitive | roles/owner, roles/editor | Almost never on a workload — project-wide, far too broad. |
| Predefined | roles/storage.objectAdmin | Default. Google-maintained, scoped to one service. |
| Custom | your own permission list | Only when no predefined role fits — you now own the upkeep. |
Two hard rules, each with teeth:
Editor on the whole project, so a single RCE in your container = full project
takeover. Mint a dedicated SA per service and pass it explicitly (see Cloud Run).gcloud iam service-accounts create api-sa --display-name="api runtime"... keys create is
in your runbook, the runbook is wrong.The predefined-role catalog, WIF for keyless CI, SA impersonation, IAM Recommender and
Conditions live in references/iam-and-auth.md.
Minimal safe deploy: dedicated runtime SA, explicit region, no anonymous ingress.
gcloud run deploy api \
--image=europe-west1-docker.pkg.dev/acme-prod/app/api:1.4.0 \
--region=europe-west1 \
--service-account=api-sa@acme-prod.iam.gserviceaccount.com \
--no-allow-unauthenticated--service-account sets the runtime identity. Omit it and the revision runs as the
over-privileged default compute SA — the rule-1 footgun. Always pass it.--no-allow-unauthenticated keeps the service private (callers need
roles/run.invoker). Flip to --allow-unauthenticated only for a genuinely public
endpoint. Open by accident and you have shipped an unauthenticated API.Production knobs:
# Cold starts hurt: pin a warm instance and boost CPU on startup.
# Default min-instances is 0 (scales to zero); default max is 100 (your cost ceiling).
gcloud run services update api --region=europe-west1 \
--min-instances=1 --cpu-boost --max-instances=20Config vs secrets — secrets never go in --set-env-vars, because env vars show up
in plaintext in describe, logs and the console. Mount them from Secret Manager:
gcloud run deploy api --region=europe-west1 \
--service-account=api-sa@acme-prod.iam.gserviceaccount.com \
--set-env-vars="LOG_LEVEL=info" \
--set-secrets="DB_PASSWORD=db-password:latest"Create buckets locked down; loosen deliberately, never the reverse.
gcloud storage buckets create gs://acme-prod-uploads \
--location=europe-west1 \
--uniform-bucket-level-access \
--public-access-prevention--uniform-bucket-level-access (UBLA) turns off per-object ACLs so access is only
IAM — one place to reason about, one place to audit. There is a 90-day window to
revert UBLA; after that it is permanent, so set it at creation.--public-access-prevention makes a public grant impossible even by mistake.Grant access to the workload, not the world:
gcloud storage buckets add-iam-policy-binding gs://acme-prod-uploads \
--member="serviceAccount:api-sa@acme-prod.iam.gserviceaccount.com" \
--role="roles/storage.objectAdmin"Need to hand a file to an anonymous browser? Use a signed URL (time-limited),
never allUsers:
gcloud storage sign-url gs://acme-prod-uploads/report.pdf --duration=15m \
--impersonate-service-account=api-sa@acme-prod.iam.gserviceaccount.com--impersonate-service-account is not decoration. Signing needs a private key, and the
keyless model this skill mandates (attached SA, no JSON keys) hands you an ADC token,
not a key. The flag tells gcloud to sign via the IAM signBlob API instead — so the
caller must hold roles/iam.serviceAccountTokenCreator (which grants
iam.serviceAccounts.signBlob) on api-sa. Without it, the command fails or
silently wants a key file, which would reopen the rule-2 footgun. Grant it once:
gcloud iam service-accounts add-iam-policy-binding \
api-sa@acme-prod.iam.gserviceaccount.com \
--member="serviceAccount:api-sa@acme-prod.iam.gserviceaccount.com" \
--role="roles/iam.serviceAccountTokenCreator"Durability one-liners:
gcloud storage buckets update gs://acme-prod-uploads --versioning # keep old versions
gcloud storage buckets update gs://acme-prod-uploads \
--lifecycle-file=lifecycle.json # auto-expire/age outCreate a managed Postgres with a private IP and no public IP — the public IP is the part that gets scanned and brute-forced.
gcloud sql instances create acme-db \
--database-version=POSTGRES_16 \
--edition=ENTERPRISE \
--region=europe-west1 \
--tier=db-f1-micro \
--no-assign-ip \
--network=projects/acme-prod/global/networks/default--edition=ENTERPRISE is mandatory here, not optional. From POSTGRES_16 up the
default edition is Enterprise Plus, which only runs on N2/C4A/N4 machine series — the
shared-core db-f1-micro is an Enterprise-only tier, so the create fails without
this flag. Want the cheapest box? Stay on Enterprise. Reach for Enterprise Plus only
when you actually need its dedicated cores and faster failover, and drop --tier for a
--cpu/--memory pair then.
Put the password in Secret Manager, not in a flag or a file:
gcloud sql users create app --instance=acme-db --password="$(openssl rand -base64 24)"
printf '%s' "$(openssl rand -base64 24)" | \
gcloud secrets create db-password --data-file=-Attach the instance to Cloud Run — serverless connects over a Unix socket, no Auth Proxy sidecar needed:
gcloud run deploy api --region=europe-west1 \
--service-account=api-sa@acme-prod.iam.gserviceaccount.com \
--add-cloudsql-instances=acme-prod:europe-west1:acme-db \
--set-secrets="DB_PASSWORD=db-password:latest"
# In the app, connect via the socket:
# host=/cloudsql/acme-prod:europe-west1:acme-dbThe Cloud SQL Auth Proxy (short-lived certs, TLS 1.3) is for connecting from
outside — local dev or a non-serverless host — not for Cloud Run. Direct VPC egress vs
legacy connectors, private IP / PSC, proxy invocation and pooling are in
references/networking-and-sql.md.
One service, one dedicated SA, exactly the roles it needs — and nothing else.
# Identity
gcloud iam service-accounts create api-sa --display-name="api runtime"
SA=api-sa@acme-prod.iam.gserviceaccount.com
# Exactly four predefined roles. No Editor, no Owner.
gcloud projects add-iam-policy-binding acme-prod \
--member="serviceAccount:$SA" --role="roles/cloudsql.client"
gcloud secrets add-iam-policy-binding db-password \
--member="serviceAccount:$SA" --role="roles/secretmanager.secretAccessor"
gcloud storage buckets add-iam-policy-binding gs://acme-prod-uploads \
--member="serviceAccount:$SA" --role="roles/storage.objectAdmin"
# Deploy with all three wired in
gcloud run deploy api --region=europe-west1 \
--image=europe-west1-docker.pkg.dev/acme-prod/app/api:1.4.0 \
--service-account="$SA" \
--no-allow-unauthenticated \
--add-cloudsql-instances=acme-prod:europe-west1:acme-db \
--set-secrets="DB_PASSWORD=db-password:latest" \
--set-env-vars="BUCKET=acme-prod-uploads"Note the scoping: cloudsql.client is project-wide (the role needs it), but the
storage and secret grants are bound to the specific bucket and secret, not the
project. Grant narrow.
Copy-paste runbooks for each piece — image build and push, private container deploy,
attach SQL, mount a secret, full teardown — are in
references/deploy-recipes.md.
--min-instances=0 on staging.--max-instances and a budget alert (full command in
references/deploy-recipes.md):gcloud billing budgets create --billing-account=0X0X0X-0X0X0X-0X0X0X \
--display-name="acme-prod" --budget-amount=50 \
--threshold-rule=percent=0.9gcloud run services delete api --region=europe-west1
gcloud sql instances delete acme-db
gcloud storage rm --recursive gs://acme-prod-uploads| Bad | Good | Why |
|---|---|---|
Deploy with no --service-account | Pass a dedicated per-service SA | Default compute SA has Editor; an RCE becomes project takeover |
gcloud iam service-accounts keys create key.json | Attached SA + Workload Identity Federation | JSON keys are long-lived, leak, and are rarely rotated |
--role=roles/editor on a workload SA | Scoped predefined roles (cloudsql.client, …) | Primitive roles grant far more than the service needs |
Bucket public via allUsers | Signed URL via --impersonate-service-account (+ Token Creator) | A public bucket is a data leak; keyless signing needs signBlob, not a key file |
| Bucket created without UBLA/PAP | --uniform-bucket-level-access --public-access-prevention at create | ACLs sprawl; PAP blocks accidental public grants |
Cloud SQL with public IP open to 0.0.0.0/0 | --no-assign-ip + private IP / Auth Proxy | Public DB IPs get scanned and brute-forced |
Secrets in --set-env-vars | --set-secrets from Secret Manager | Env vars are plaintext in describe, logs, console |
gcloud services enable everything | Enable only the APIs you use | Each API widens attack surface; some bill on enable |
No --min-instances on prod, then blame cold starts | --min-instances=1 --cpu-boost on prod | Scale-to-zero is the cause; pin a warm instance |
| Auth Proxy sidecar on Cloud Run | --add-cloudsql-instances + /cloudsql/... socket | Serverless connects natively; the proxy is for outside-VPC |
scripts/verify.sh is an offline static linter (no GCP calls, no network) over files
that contain gcloud command blocks. It flags the unsafe patterns above: JSON key
creation, roles/owner|roles/editor bound to a service account, bucket creates missing
UBLA/PAP, Cloud SQL public IP without private IP, and Cloud Run deploys missing
--service-account.
bash scripts/verify.sh path/to/runbook.sh # one file
bash scripts/verify.sh path/to/dir/ # recurse a directoryIt prints PASS/FAIL per check and exits nonzero on any FAIL. An empty or
clean target passes (exit 0).
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/gcp-essentials of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
GCP Essentials next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GCP Essentials this skillericrisco/rsc-harness | 156 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Broccoli Oss GCP Deploybesimple-oss/broccoli | 286 | — | ~4.1k | Automated safety check: Pass | MIT | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 259 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| Multi Cloud ArchitectureHermeticOrmus/LibreUIUX-Claude-Code | 111 | 10 repos | ~1.2k | Automated safety check: Pass | MIT | |
| Aurora Dsqlaws/agent-toolkit-for-aws | 2.8k | — | ~9.6k | Automated safety check: Pass | Apache-2.0 | |
| Dd GCP Integrationdatadog-labs/agent-skills | 177 | — | ~8k | Automated safety check: Notes | MIT |
besimple-oss/broccoli
Deploy this repository to a new Google Cloud project using the repo's existing Cloud Run, Cloud Run Jobs, Cloud SQL, Secret Manager, and Artifact Registry scripts.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
HermeticOrmus/LibreUIUX-Claude-Code
Design multi-cloud architectures using a decision framework to select and integrate services across AWS, Azure, and GCP.
aws/agent-toolkit-for-aws
Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless…
datadog-labs/agent-skills
Set up the Datadog Google Cloud integration with Terraform - creates a service account in the host project, lets Datadog's delegate principal impersonate it via roles/iam.serviceAccountTokenCreator…
aws/agent-toolkit-for-aws
Migrate workloads from Google Cloud Platform to AWS — plus AI and agentic workloads from any provider.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Categories
A skill your agent uses when running a small product on core Google Cloud via the gcloud CLI: a project, Cloud Run deploys, a locked-down Cloud Storage bucket, managed Cloud SQL, and least-privilege…. GCP Essentials is an agent skill from ericrisco/rsc-harness. Use when running a small product on core Google Cloud via the gcloud CLI: a project, Cloud Run deploys, a locked-down Cloud Storage bucket, managed Cloud SQL, and least-privilege IAM wiring them together.
GCP Essentials fits situations like: running a small product on core Google Cloud via the gcloud CLI: a project; cloud Run deploys; A locked-down Cloud Storage bucket; managed Cloud SQL.
Run `npx skills add ericrisco/rsc-harness --skill gcp-essentials -a claude-code`. Or copy the skill folder (skills/gcp-essentials in ericrisco/rsc-harness) into .claude/skills/gcp-essentials in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill gcp-essentials -a codex`. Or copy the skill folder (skills/gcp-essentials in ericrisco/rsc-harness) into .agents/skills/gcp-essentials in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill gcp-essentials -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gcp-essentials, .gemini/skills/gcp-essentials, .github/skills/gcp-essentials and .opencode/skills/gcp-essentials in your project.
Going by SKILL.md and its folder, GCP Essentials needs a shell for the scripts in its folder, the command-line tools its instructions call (gcloud, openssl and bash) and credentials named DB_PASSWORD. Our summary lists: A Bash shell; Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
GCP Essentials is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with GCP Essentials: Broccoli Oss GCP Deploy (besimple-oss/broccoli, 286 stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars), Multi Cloud Architecture (HermeticOrmus/LibreUIUX-Claude-Code, 111 stars) and Aurora Dsql (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.